]> git.ipfire.org Git - thirdparty/linux.git/commit
net/smc: fix socket use-after-free during link group termination
authorXuanqiang Luo <luoxuanqiang@kylinos.cn>
Thu, 23 Jul 2026 10:54:54 +0000 (18:54 +0800)
committerPaolo Abeni <pabeni@redhat.com>
Tue, 28 Jul 2026 09:22:43 +0000 (11:22 +0200)
commitf621d6ebeebb6374342571e4ddf45fdbc420f6cd
tree2a5fe2e7704cd82b08165fff2ec8b5d5c6a569de
parentaef96eead2860cbfa371e4471d4f04412213b958
net/smc: fix socket use-after-free during link group termination

__smc_lgr_terminate() drops conns_lock after finding a connection in
lgr->conns_all, but before taking a reference on its socket. The connection
is embedded in the socket, and its registration reference protects it only
while the connection remains in the tree.

A concurrent close can unregister the connection and drop that reference,
freeing the socket before the termination worker reaches sock_hold().

The race is reachable when close overlaps link group termination.
Local stress testing reproduced the use-after-free and KASAN reported:

  BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]
  Write of size 4 by task kworker/3:3
  Workqueue: events smc_lgr_terminate_work [smc]
  __smc_lgr_terminate.part.0 [smc]

The socket was allocated by smc_create(), freed through
slab_free_after_rcu_debug(), and was followed by:

  refcount_t: addition on 0; use-after-free.
  __smc_lgr_terminate.part.0 [smc]

Take the socket reference while conns_lock still protects the tree entry.
The unregister path then cannot drop the last reference until termination
has finished using the socket.

Fixes: 69318b5215f2 ("net/smc: improve abnormal termination locking")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
Link: https://patch.msgid.link/20260723105454.87016-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
net/smc/smc_core.c